Impact
A flaw in Feast allows a remote attacker to store a malicious user‑defined function serialized with the "dill" library, leading to unauthenticated arbitrary code execution on the feature server when the system is in its default configuration. An attacker who can authenticate to the registry can also bypass authorization checks during deserialization and obtain arbitrary code execution on the registry server, potentially enabling cross‑tenant data access and lateral movement within the overall system. This is a classic example of unsafe deserialization that permits remote code execution and privilege escalation.
Affected Systems
The affected product is Red Hat OpenShift AI (RHOAI) on both the feature server component and the registry server component. No specific version information is provided in the CNA data, so all current RHOAI deployments that run the default Feast configuration are considered at risk until a vendor‑issued fix is applied.
Risk and Exploitability
The CVSS score is 9.9, indicating critical severity. The EPSS score is not available, so current data does not quantify the exploitation probability; however, the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is network‑based access to the Feast feature server; unauthenticated attackers can trigger exploitation by pushing a malicious UDF, while authenticated attackers can target the registry server for deeper compromise. The high severity and the ability to execute code without authentication make this vulnerability a top‑priority risk that could compromise data integrity and confidentiality across tenants.
OpenCVE Enrichment